CVE-2015-4495
KEVmassSame-Origin Policy Bypass in Mozilla Firefox Allows Arbitrary File Reading
CISA: Mozilla Firefox Security Feature Bypass Vulnerability
CVE-2015-4495 is a security feature (same-origin policy) bypass in the PDF viewer bundled with Mozilla Firefox. It is triggered when a user opens a maliciously crafted PDF document in Firefox, which lets the document's JavaScript escape the PDF viewer's origin restrictions. A successful attacker can read arbitrary files from the user's system and, in some environments (notably Windows, where helper applications can be launched), gain privileges or execute code; the observed in-the-wild attacks stole sensitive data and passwords. Any user running an affected Firefox build is affected; the flaw was exploited as a 0-day in August 2015 and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-05-25 (ransomware use unknown). EPSS currently assigns a 71.4% probability of exploitation within the next 30 days, and the required action is to apply updates per vendor instructions.
What to do: Update Firefox to at least version 39.0.3, Firefox ESR 38.1.1, or Firefox ESR 31.8 (any later release also contains this 2015 fix); the priority is auditing for and upgrading legacy Firefox installations to satisfy the CISA KEV required action. Until patched, discourage users from opening PDFs from untrusted sources in Firefox, since a crafted PDF opened in the built-in viewer is the attack vector.
| Mozilla Firefox | Firefox releases prior to the August 2015 security updates (fixed in Firefox 39.0.3, Firefox ESR 38.1.1, and Firefox ESR 31.8 per Mozilla's advisories; the CISA |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
- Affected
- Mozilla Firefox
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Mozilla
- Products
- Firefox
- Weakness
- CWE-200